github.com
https://github.com/alkacon/opencms-core CVE-2024-5520
MEDIUM
Cross-Site Scripting stored in Alkacon OpenCMS
Record summary
CVE-2024-5520 has a selected CVSS score of 6.4 (medium).
Description
Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user with sufficient privileges to create and modify web pages through the admin panel, can execute malicious JavaScript code, after inserting code in the “title” field.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 30, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
OpenCMSBrowse Alkacon / OpenCMSDefault status: unaffected | CVE List | 16 | affected |
org.opencms:opencms-coreBrowse Maven / org.opencms:opencms-core | GitHub Advisory | 16.0 | affected |
| 16.0 to < 17.0 · Fixed in 17.0 | affected |
References
4github.com
https://github.com/alkacon/opencms-core/commit/b05a5aca0f2b03042ddf2b2bb45fe2243a4084a7 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-5520 incibe.es
https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-stored-alkacon-opencms